As cited
Copy frozen at (site build).
breaches incidents
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Cyber extortion group FulcrumSec exploited hardcoded credentials found in Novo Nordisk's public-facing infrastructure to access the pharmaceutical company's systems. The breach, part of a campaign called "Hardcoded Horrorshow", demonstrates the group's focus on extracting cloud-based data rather than targeting endpoints.
Why it matters: Organizations that expose credentials in repositories, configuration files, or public infrastructure face immediate extortion risk; practitioners must scan and rotate hardcoded secrets from version control and deployment pipelines.
- First seen by Cybersecurity Tracker